Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-21-2013, 11:00 PM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Exploit v
« Previous 1 2 3 4 5 ... 15 Next »

[Tutor] PHP Volunteer Management (get_messages.php) SQL Injection Vulnerabilities

Home General Computer Multimedia Business Lounge

Pages (2): « Previous 1 2
Post Reply 
Tweet
Threaded Mode | Linear Mode
Tutor PHP Volunteer Management (get_messages.php) SQL Injection Vulnerabilities
04-30-2012, 12:56 PM
Post: #11
dhelpi7 Offline
gue ganteng,thx
Posts: 303
Joined: Dec 2010
Reputation: 23
RE: PHP Volunteer Management (get_messages.php) SQL Injection Vulnerabilities
mantap bg udel keren bener dah te.op.pe be.ge.te (Top Bgt) ketawa
Find all posts by this user
Quote this message in a reply
04-30-2012, 01:44 PM
Post: #12
eidelweiss Offline
Devilzc0der
*****
DC Security Grup
Posts: 1,535
Joined: Mar 2010
Reputation: 69
RE: PHP Volunteer Management (get_messages.php) SQL Injection Vulnerabilities
sebener nya ada xxs nya jg , dan ada file lain yg kena sql tapi udah di publish sama nick G13..

Nah yg ini hasil analysis ulang ane dan ntah hilaf atau gk keliatan dia nya makanya gk di publish ,

jadi di file get_messages.php ternyata jg kena sql c0de nya bisa di liat nich:

Code:
<?php
define('INCLUDE_CHECK',true);
include '../../../config/connect.php';
$id = $_GET['id'];
$query = "SELECT * FROM messages, volunteers WHERE message_to_id = '$id' AND message_from_id = volunteer_id ORDER BY message_state, message_id";
$mysql_result = mysql_query($query);
$result = array();
while ($row = mysql_fetch_assoc($mysql_result)) {
$result[] = $row;
}
$data = json_encode($result);

print_r($data);
?>

$id = $_GET['id']; <= 1
$query = "SELECT * FROM messages, volunteers WHERE message_to_id = '$id'
AND message_from_id = volunteer_id ORDER BY message_state, message_id";

Nah yg Ane merahin tuh kesalahan pada c0ding nya . CMIIW

peace
Visit this user's website Find all posts by this user
Quote this message in a reply
04-30-2012, 03:00 PM
Post: #13
tempe_mendoan Offline
Banned
**
Moderators
Posts: 666
Joined: Mar 2010
Reputation: 16
RE: PHP Volunteer Management (get_messages.php) SQL Injection Vulnerabilities
wuih exploiter takut
Visit this user's website Find all posts by this user
Quote this message in a reply
04-30-2012, 04:27 PM
Post: #14
anharku Offline
./Devilz Advisor
Posts: 505
Joined: Jul 2010
Reputation: 29
RE: PHP Volunteer Management (get_messages.php) SQL Injection Vulnerabilities
wew keren....
ajarin dong om cara nyari POC nya
Find all posts by this user
Quote this message in a reply
05-01-2012, 03:56 AM
Post: #15
akatsuchi Offline
./Devilz Advisor
Posts: 578
Joined: Feb 2010
Reputation: 8
RE: PHP Volunteer Management (get_messages.php) SQL Injection Vulnerabilities
woh...flood
Find all posts by this user
Quote this message in a reply
05-01-2012, 01:46 PM
Post: #16
chiboga Offline
./Devilz Advisor
Posts: 694
Joined: Nov 2011
Reputation: 24
RE: PHP Volunteer Management (get_messages.php) SQL Injection Vulnerabilities
ijin pelajari dulu ah ...!!!

smangatsmangat
Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Pages (2): « Previous 1 2
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  [Tutor] Hotel Booking Portal v0.1 Multiple Vulnerabilities Reborn Of Code 9 341 10-30-2012 12:42 PM
Last Post: xnuxer_001
  [Tutor] Joomla Component - com_filecabinet Vulnerable to SQL Injection p0pc0rn 11 540 07-29-2012 08:28 AM
Last Post: blackhariki
Bug RevolutionTechnologies - SQL Injection Vulnerability nuxbie_cyber 6 220 06-14-2012 11:20 AM
Last Post: Anonymous33
Bug Joomla Component SpiderCalendar SQL Injection/Fatal error KotoM 9 254 05-31-2012 02:30 AM
Last Post: 4k3ch1
Bug Joomla Module ccNewsletter SQL Injection KotoM 16 478 05-27-2012 10:10 PM
Last Post: reyhanwiva
Bug [Tutor] Exploit ( Endonesia 8.5 SQL Injection ) ohara_inamiji 27 1,434 03-19-2012 05:13 PM
Last Post: ohara_inamiji
Bug [Tutor] Exploit (com_ Simplest Forum) Blind SQL Injection ohara_inamiji 10 872 02-23-2012 09:51 AM
Last Post: irash
Bug Base Content Management System Lennox Industries - SQL Injection Vulnerability nuxbie_cyber 12 235 02-23-2012 09:45 AM
Last Post: irash
Bug Jcow 4.x.x SQL Injection KotoM 17 453 02-16-2012 08:40 PM
Last Post: try4error
Bug [Tutor] Joomla Advanced Search SQL Injection POST methode (com_cb_search) tian hv 8 386 02-08-2012 02:40 AM
Last Post: ciresoft49

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-21-2013, 11:00 PM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE